This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware....infections....help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

you fixed my computer so well recently,  this is my son's   He doesnt keep up with things, and complains of slow browser issues, unable to launch programs.  as well as pop ups.   Please work your magic again  and thanks

 

Here are the logs you requested.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-08-27 12:16:44
—————————–
12:16:44.570    OS Version: Windows x64 6.1.7601 Service Pack 1
12:16:44.571    Number of processors: 4 586 0x3A09
12:16:44.571    ComputerName: RICHARD-PC  UserName: richard
12:16:46.282    Initialize success
12:16:46.523    VM: initialized successfully
12:16:46.525    VM: Intel CPU BiosDisabled 
12:18:25.328    AVAST engine defs: 16082500
12:22:29.266    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
12:22:29.268    Disk 0 Vendor: TOSHIBA_ MS2O Size: 953869MB BusType: 3
12:22:29.353    Disk 0 MBR read successfully
12:22:29.356    Disk 0 MBR scan
12:22:29.361    Disk 0 Windows 7 default MBR code
12:22:29.365    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
12:22:29.368    Disk 0 Boot: NTFS     code=1
12:22:29.380    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       953767 MB offset 206848
12:22:29.404    Disk 0 scanning C:\Windows\system32\drivers
12:22:36.782    Service scanning
12:22:56.891    Modules scanning
12:22:56.900    Disk 0 trace - called modules:
12:22:56.917    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys ACPI.sys iaStor.sys hal.dll 
12:22:56.922    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007866060]
12:22:56.927    3 CLASSPNP.SYS[fffff88001c9a43f] -> nt!IofCallDriver -> [0xfffffa80076a6a90]
12:22:56.932    5 iaStorF.sys[fffff8800169f2fa] -> nt!IofCallDriver -> [0xfffffa8007513d10]
12:22:56.937    7 ACPI.sys[fffff88000f107a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007516050]
12:22:57.920    AVAST engine scan C:\Windows
12:22:59.816    AVAST engine scan C:\Windows\system32
12:24:58.273    AVAST engine scan C:\Windows\system32\drivers
12:25:07.235    AVAST engine scan C:\Users\richard
12:26:08.498    Disk 0 MBR has been saved successfully to "C:\Users\richard\Desktop\MBR.dat"
12:26:08.502    The log file has been saved successfully to "C:\Users\richard\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-08-2016
Ran by [removed] (administrator) on RICHARD-PC (27-08-2016 12:37:38)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Webroot) C:\Program Files\Webroot\WRSA.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(OpenDownloadManager.com) C:\Program Files (x86)\OpenDownloaderManager\ODM.exe
() C:\Users\richard\AppData\Roaming\ACEStream\engine\ace_engine.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Samsung Electronics Co. Ltd.) C:\Users\richard\AppData\Roaming\Verizon\UA_ar\UtilityApplication.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Users\richard\AppData\Roaming\ACEStream\updater\ace_update.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Farbar) C:\Users\richard\Downloads\FRST64 (1).exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {0a44b838-5bea-11e4-990a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {5f725559-8e23-11e2-a232-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {6646635f-85f7-11e3-b40f-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {74e0c3ad-1f94-11e5-8d4a-60a44c3dd8c8} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\MountPoints2: {f2cd7dbd-84c1-11e2-b5c7-806e6f6e6963} - D:\MCF_MadameFate.exe
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-18]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk [2013-03-04]
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2016-08-27]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{29DCBCA3-040D-4832-8D35-34BEB5274039}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{A183BB9B-B707-4E38-BC51-E5EA52B835BF}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com
SearchScopes: HKLM -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = 
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2016-08-05] (Webroot)
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15] (Intel Security)
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2016-08-05] (Webroot)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15] (Intel Security)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\zzpafahk.default-1439605903410
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-18] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-18] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin -> C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-07-28] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-441904776-594677368-125994074-1001: @acestream.net/acestreamplugin,version=3.1.2 -> C:\Users\richard\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-08-06] (Innovative Digital Technologies)
FF Extension: (Ace Stream Web Extension) - C:\Users\richard\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2015-12-18]
FF Extension: (Hide My IP) - C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\zzpafahk.default-1439605903410\Extensions\[removed] [2016-07-05]
FF Extension: (Facebook™ Disconnect) - C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\zzpafahk.default-1439605903410\Extensions\[removed] [2016-07-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: (Webroot Filtering Extension) - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2016-08-05]
FF HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Firefox\Extensions: [[removed]] - C:\Users\richard\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://facebook.com/"
CHR Profile: C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-26]
CHR Extension: (Google Search) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Search by Image (by Google)) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2016-02-20]
CHR Extension: (Google Docs Offline) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Grammarly for Chrome) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2016-08-20]
CHR Extension: (Webroot Filtering Extension) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2016-08-04]
CHR Extension: (Ace Stream Web Extension) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-08-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-21]
CHR HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc.)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark Corporation)
R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3026584 2016-05-06] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [327944 2016-07-18] (McAfee, Inc.)
S3 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [837848 2016-02-02] (Secunia)
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [908256 2016-07-14] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-07-14] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-07-14] (McAfee, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [937008 2016-08-17] (Webroot)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2012-01-06] (Asmedia Technology)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [23832 2011-12-02] (Intel Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] ()
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [139088 2016-08-27] (Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [54512 2016-08-05] (Webroot)
U0 SR; no ImagePath
U2 srservice; no ImagePath
U3 aswMBR; \??\C:\Users\richard\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\richard\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-08-27 12:37 - 2016-08-27 12:37 - 00027224 _____ C:\Users\richard\Downloads\FRST.txt
2016-08-27 12:36 - 2016-08-27 12:37 - 00000000 ____D C:\FRST
2016-08-27 12:35 - 2016-08-27 12:36 - 02396672 _____ (Farbar) C:\Users\richard\Downloads\FRST64 (1).exe
2016-08-27 12:31 - 2016-08-27 12:32 - 02396672 _____ (Farbar) C:\Users\richard\Downloads\FRST64.exe
2016-08-27 12:30 - 2016-08-27 12:30 - 00000000 ____D C:\Users\richard\Desktop\whatthetechstuff
2016-08-27 12:28 - 2016-08-27 12:28 - 01746944 _____ (Farbar) C:\Users\richard\Downloads\FRST.exe
2016-08-27 12:28 - 2016-08-27 12:28 - 01746944 _____ (Farbar) C:\Users\richard\Downloads\FRST (1).exe
2016-08-27 12:26 - 2016-08-27 12:26 - 00002063 _____ C:\Users\richard\Desktop\aswMBR.txt
2016-08-27 12:16 - 2016-08-27 12:16 - 05198336 _____ (AVAST Software) C:\Users\richard\Downloads\aswMBR (2).exe
2016-08-27 12:15 - 2016-08-27 12:15 - 05198336 _____ (AVAST Software) C:\Users\richard\Downloads\aswMBR.exe
2016-08-27 12:15 - 2016-08-27 12:15 - 05198336 _____ (AVAST Software) C:\Users\richard\Downloads\aswMBR (1).exe
2016-08-27 12:08 - 2016-08-27 12:08 - 00000000 ____D C:\Windows\pss
2016-08-27 12:06 - 2016-08-27 12:06 - 00389478 _____ C:\Users\richard\Documents\cc_20160827_120617.reg
2016-08-27 12:06 - 2016-08-27 12:06 - 00006392 _____ C:\Users\richard\Documents\cc_20160827_120633.reg
2016-08-27 11:54 - 2016-08-27 11:54 - 00002798 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-08-27 11:54 - 2016-08-27 11:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-08-27 11:54 - 2016-08-27 11:54 - 00000000 ____D C:\Program Files\CCleaner
2016-08-27 11:53 - 2016-08-27 11:54 - 08227032 _____ (Piriform Ltd) C:\Users\richard\Downloads\ccsetup521.exe
2016-08-27 11:37 - 2016-08-27 11:38 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-27 11:37 - 2016-08-27 11:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-27 11:37 - 2016-08-27 11:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-27 11:37 - 2016-08-27 11:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-27 11:37 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-08-27 11:37 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-08-27 11:37 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-08-27 11:35 - 2016-08-27 11:35 - 22851472 _____ (Malwarebytes ) C:\Users\richard\Downloads\mbam-setup-cnet.35891-2.2.1.1043.exe
2016-08-27 11:16 - 2016-08-27 11:16 - 00000994 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-08-27 11:16 - 2016-08-27 11:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-08-27 11:16 - 2016-08-27 11:16 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-08-27 11:14 - 2016-08-27 11:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-08-27 11:14 - 2016-08-27 11:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-08-27 11:12 - 2016-08-27 11:12 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2016-08-27 11:06 - 2016-08-27 11:06 - 00000000 ____D C:\Users\richard\AppData\Local\Secunia PSI
2016-08-27 11:06 - 2016-08-27 11:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2016-08-27 11:05 - 2016-08-27 11:05 - 05490752 _____ (Secunia) C:\Users\richard\Downloads\PSISetup (1).exe
2016-08-27 11:04 - 2016-08-27 11:04 - 05490752 _____ (Secunia) C:\Users\richard\Downloads\PSISetup.exe
2016-08-24 20:24 - 2016-08-27 11:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-18 17:08 - 2016-08-18 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-08-16 12:40 - 2016-07-08 10:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-08-16 12:40 - 2016-07-08 10:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-08-13 15:26 - 2016-08-13 15:26 - 16597254 _____ C:\Users\richard\Downloads\yesjulzvideo.mov
2016-08-09 19:19 - 2016-08-02 09:54 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-09 19:19 - 2016-08-02 09:08 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-09 19:19 - 2016-08-02 01:54 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-09 19:19 - 2016-08-02 01:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-08-09 19:19 - 2016-08-02 01:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-08-09 19:19 - 2016-08-02 01:32 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-09 19:19 - 2016-08-02 01:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-08-09 19:19 - 2016-08-02 01:31 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-09 19:19 - 2016-08-02 01:31 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-08-09 19:19 - 2016-08-02 01:31 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-08-09 19:19 - 2016-08-02 01:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-08-09 19:19 - 2016-08-02 01:24 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-08-09 19:19 - 2016-08-02 01:23 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-08-09 19:19 - 2016-08-02 01:20 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-09 19:19 - 2016-08-02 01:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-08-09 19:19 - 2016-08-02 01:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-08-09 19:19 - 2016-08-02 01:18 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-09 19:19 - 2016-08-02 01:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-09 19:19 - 2016-08-02 01:18 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-08-09 19:19 - 2016-08-02 01:11 - 00969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-08-09 19:19 - 2016-08-02 01:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-08-09 19:19 - 2016-08-02 01:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-08-09 19:19 - 2016-08-02 01:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-08-09 19:19 - 2016-08-02 00:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-08-09 19:19 - 2016-08-02 00:56 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-08-09 19:19 - 2016-08-02 00:55 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-08-09 19:19 - 2016-08-02 00:54 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-09 19:19 - 2016-08-02 00:53 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-08-09 19:19 - 2016-08-02 00:51 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-09 19:19 - 2016-08-02 00:51 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-08-09 19:19 - 2016-08-02 00:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-08-09 19:19 - 2016-08-02 00:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-08-09 19:19 - 2016-08-02 00:51 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-08-09 19:19 - 2016-08-02 00:50 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-08-09 19:19 - 2016-08-02 00:47 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-09 19:19 - 2016-08-02 00:45 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-08-09 19:19 - 2016-08-02 00:44 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-08-09 19:19 - 2016-08-02 00:42 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-08-09 19:19 - 2016-08-02 00:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-09 19:19 - 2016-08-02 00:41 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-08-09 19:19 - 2016-08-02 00:41 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-08-09 19:19 - 2016-08-02 00:40 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-08-09 19:19 - 2016-08-02 00:38 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-09 19:19 - 2016-08-02 00:38 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-09 19:19 - 2016-08-02 00:37 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-08-09 19:19 - 2016-08-02 00:36 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-09 19:19 - 2016-08-02 00:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-08-09 19:19 - 2016-08-02 00:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-08-09 19:19 - 2016-08-02 00:28 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-09 19:19 - 2016-08-02 00:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-08-09 19:19 - 2016-08-02 00:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-08-09 19:19 - 2016-08-02 00:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-08-09 19:19 - 2016-08-02 00:24 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-08-09 19:19 - 2016-08-02 00:23 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-09 19:19 - 2016-08-02 00:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-08-09 19:19 - 2016-08-02 00:21 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-09 19:19 - 2016-08-02 00:16 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-08-09 19:19 - 2016-08-02 00:15 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-09 19:19 - 2016-08-02 00:14 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-09 19:19 - 2016-08-02 00:14 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-08-09 19:19 - 2016-08-02 00:11 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-09 19:19 - 2016-08-02 00:10 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-09 19:19 - 2016-08-01 23:59 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-09 19:19 - 2016-08-01 23:56 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-09 19:19 - 2016-08-01 23:53 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-09 19:19 - 2016-08-01 23:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-09 19:19 - 2016-07-08 10:37 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-09 19:19 - 2016-07-08 10:37 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-08-09 19:19 - 2016-07-08 10:32 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-08-09 19:19 - 2016-07-08 10:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-08-09 19:19 - 2016-07-08 10:17 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-08-09 19:19 - 2016-07-08 10:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-08-09 19:19 - 2016-07-08 10:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-08-09 19:19 - 2016-07-08 10:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-08-09 19:19 - 2016-07-08 09:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-08-09 19:19 - 2016-07-08 09:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-08-09 19:19 - 2016-07-08 09:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-08-09 19:19 - 2016-07-08 09:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-08-09 19:19 - 2016-07-08 09:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-08-09 19:19 - 2016-07-08 09:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-08-09 19:18 - 2016-07-08 10:01 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-08-03 01:55 - 2016-08-03 01:55 - 01645801 _____ C:\Users\richard\Downloads\PantherMap.PDF
2016-07-31 19:13 - 2016-07-31 20:45 - 00003058 _____ C:\Users\richard\Downloads\firefox-patch.js
2016-07-28 17:10 - 2016-08-27 12:15 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143.job
2016-07-28 17:10 - 2016-08-27 11:01 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273.job
2016-07-28 17:10 - 2016-07-28 17:10 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143
2016-07-28 17:10 - 2016-07-28 17:10 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-08-27 12:36 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-27 12:36 - 2009-07-13 23:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-27 12:34 - 2014-02-01 13:54 - 00000000 ____D C:\Users\richard\AppData\Roaming\Open Download Manager
2016-08-27 11:58 - 2014-09-20 23:21 - 00000000 ____D C:\Windows\Minidump
2016-08-27 11:58 - 2011-03-01 17:27 - 00000000 ____D C:\Windows\Panther
2016-08-27 11:58 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\ModemLogs
2016-08-27 11:58 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-08-27 11:15 - 2013-03-13 20:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-08-27 11:15 - 2013-03-13 20:57 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-08-27 11:14 - 2015-12-25 02:25 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-08-27 11:14 - 2013-03-13 20:57 - 00000000 ____D C:\ProgramData\Adobe
2016-08-27 11:02 - 2013-03-16 10:58 - 00000000 ____D C:\Users\Public\Documents\Verizon_Android
2016-08-27 11:02 - 2013-03-13 21:45 - 00139088 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2016-08-27 11:02 - 2013-03-13 21:45 - 00000000 ____D C:\ProgramData\WRData
2016-08-27 11:01 - 2013-03-13 21:45 - 00000747 _____ C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2016-08-27 11:01 - 2013-03-13 19:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-27 11:01 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-26 19:12 - 2016-01-01 20:39 - 00345088 _____ C:\Users\richard\Desktop\FTB Reg 2016.xls
2016-08-21 23:30 - 2015-12-25 02:25 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-21 23:30 - 2014-12-25 22:34 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-08-20 08:27 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2016-08-18 17:08 - 2016-06-25 03:26 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-08-18 17:08 - 2016-06-25 02:56 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-08-17 06:24 - 2013-03-13 21:45 - 00185272 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2016-08-17 06:24 - 2013-03-13 21:45 - 00119920 _____ (Webroot) C:\Windows\system32\WRusr.dll
2016-08-13 17:21 - 2013-03-17 15:38 - 00000000 ____D C:\Users\richard\Desktop\Avatars
2016-08-10 03:25 - 2009-07-13 23:45 - 00410928 _____ C:\Windows\system32\FNTCACHE.DAT
2016-08-10 03:07 - 2013-08-15 00:44 - 00000000 ____D C:\Windows\system32\MRT
2016-08-10 03:01 - 2012-02-16 16:49 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-09 17:18 - 2009-07-14 00:08 - 00032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-08-08 21:17 - 2013-12-21 18:46 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-08 21:17 - 2013-12-21 18:46 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-08-06 16:03 - 2009-07-14 00:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-05 20:33 - 2015-02-26 04:16 - 00054512 ____T (Webroot) C:\Windows\system32\Drivers\wrUrlFlt.sys
2016-07-29 19:42 - 2013-12-21 18:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-29 19:42 - 2013-12-21 18:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-08-26 16:58
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-08-2016
Ran by [removed] (27-08-2016 12:37:57)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2013-03-14 00:42:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-441904776-594677368-125994074-500 - Administrator - Disabled)
Guest (S-1-5-21-441904776-594677368-125994074-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-441904776-594677368-125994074-1002 - Limited - Enabled)
richard (S-1-5-21-441904776-594677368-125994074-1001 - Administrator - Enabled) => C:\Users\richard
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A}
AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Ace Stream Media 3.1.2 (HKU\S-1-5-21-441904776-594677368-125994074-1001\…\AceStream) (Version: 3.1.2 - Ace Stream Media) <==== ATTENTION
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\…\{316462DB-82C6-4856-BA1F-2FDFDC08799F}) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{53A19094-2C04-A9B9-7309-3E92152D4845}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.3.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.000 - Asmedia Technology)
Canon Easy-PhotoPrint EX (HKLM-x32\…\Easy-PhotoPrint EX) (Version:  - )
Canon MG2100 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2100_series) (Version:  - )
Canon MG2100 series On-screen Manual (HKLM-x32\…\Canon MG2100 series On-screen Manual) (Version:  - )
Canon MG2100 series User Registration (HKLM-x32\…\Canon MG2100 series User Registration) (Version:  - )
Canon MP Navigator EX 5.0 (HKLM-x32\…\MP Navigator EX 5.0) (Version:  - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.21 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
File Association Helper (HKLM\…\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
Fitbit Connect (HKLM-x32\…\{9EC69368-C1C7-48BA-AD93-01EFC142DDF9}) (Version: 2.0.0.6630 - Fitbit Inc.)
Futuremark SystemInfo (HKLM-x32\…\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
GameSpy Arcade (HKLM-x32\…\GameSpy Arcade) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Intel Security True Key (HKLM\…\TrueKey) (Version: 4.4.129.1 - Intel Security)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Network Connections 17.3.63.0 (HKLM\…\PROSetDX) (Version: 17.3.63.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Madame Fate (remove only) (HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Madame Fate) (Version:  - )
Magic The Gathering Online  (HKU\S-1-5-21-441904776-594677368-125994074-1001\…\35c9d60442fbb010) (Version: 3.4.90.582 - Wizards of the Coast)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\…\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 48.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 48.0.2 (x86 en-US)) (Version: 48.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 48.0.2.6079 - Mozilla)
Open Downloader Manager (HKLM-x32\…\OpenDownloaderManager) (Version:  - Installer Technology Co)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Ralink RT2860 Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.)
Secunia PSI (3.0.0.11005) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.11005 - Secunia)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Verizon Wireless Software Upgrade Assistant - Samsung(ar) (HKLM-x32\…\{FD1408CA-47E3-45C8-B7CB-75AEB8F98DA1}) (Version: 2.13.0273 - Samsung Electronics Co., Ltd.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\…\{D3D2A5FF-55C2-4A5A-BDAC-A502A66E6B8D}) (Version: 2.13.0246 - Samsung Electronics Co., Ltd.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.4 - VideoLAN)
Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.11.70 - Webroot)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinZip 18.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {034F7BE4-01E6-4669-A2EF-FA2AC0C9E23C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-05] (Piriform Ltd)
Task: {204D31B9-4534-423F-88F8-0466AFC5D8F9} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {3690DB9B-BF80-4122-B7A6-6DA6CF55B50B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {62E5C6B1-ACB5-4C1A-96E8-0F322FACE3DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {63968242-4659-4EBD-9532-E0BD1559A60D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {85F719B8-C8CA-43C2-849D-905BBA4D32B0} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {882871F6-228A-4C1D-A564-00BDD16F6104} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {8E317570-825E-47A0-8F3A-AE59661006B1} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-05-18] (McAfee, Inc.)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B364A280-0AB9-48E1-B7ED-06A42757557E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-27] (Adobe Systems Incorporated)
Task: {BDE7241D-F37A-4748-820E-C0D22FF79E38} - System32\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1e91cd5856273.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1e91cd5f87143.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-12-17 19:26 - 2016-05-19 01:55 - 00027000 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\ace_engine.exe
2015-11-11 02:17 - 2015-11-11 02:17 - 00027000 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\ace_update.exe
2012-11-23 12:40 - 2012-11-23 12:40 - 03516416 _____ () C:\Program Files (x86)\OpenDownloaderManager\fdmbtsupp.dll
2015-12-17 19:27 - 2016-05-19 01:55 - 00314880 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.Core.pyd
2011-06-12 08:09 - 2011-06-12 08:09 - 00038400 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_socket.pyd
2011-06-12 08:09 - 2011-06-12 08:09 - 00720896 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_ssl.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00287232 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_hashlib.pyd
2015-04-16 07:27 - 2015-04-16 07:27 - 00018944 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pycompat.pyd
2014-01-23 06:37 - 2014-01-23 06:37 - 00036352 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_psutil_mswindows.pyd
2012-02-07 11:37 - 2012-02-07 11:37 - 00098816 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\win32api.pyd
2012-02-07 11:35 - 2012-02-07 11:35 - 00110080 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\pywintypes27.dll
2012-02-07 11:38 - 2012-02-07 11:38 - 00358912 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\pythoncom27.dll
2012-02-07 11:36 - 2012-02-07 11:36 - 00111616 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\win32file.pyd
2012-02-07 11:36 - 2012-02-07 11:36 - 00024064 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\win32pdh.pyd
2015-04-16 07:27 - 2015-04-16 07:27 - 02386432 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pywebrtc.pyd
2015-12-17 19:24 - 2016-05-19 01:55 - 03031552 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.live.pyd
2013-12-21 08:20 - 2013-12-21 08:20 - 00053248 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_blist.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00106496 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\_ctypes.pyd
2013-12-21 08:20 - 2013-12-21 08:20 - 00040448 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\bitarray._bitarray.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00011776 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\select.pyd
2015-12-17 16:19 - 2016-05-19 01:55 - 00242792 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pysegmenter.pyd
2015-04-16 07:29 - 2015-04-16 07:29 - 00112142 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\libgcc_s_dw2-1.dll
2011-01-18 16:56 - 2011-01-18 16:56 - 00334336 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\M2Crypto.__m2crypto.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00152576 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\pyexpat.pyd
2011-02-13 10:02 - 2011-02-13 10:02 - 00031232 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\Crypto.Cipher.AES.pyd
2015-12-17 19:46 - 2016-05-19 01:55 - 04481024 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\acestreamengine.CoreApp.pyd
2016-05-19 06:16 - 2016-05-19 01:55 - 00014848 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\netifaces.pyd
2010-10-10 17:23 - 2010-10-10 17:23 - 00723968 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\apsw.pyd
2013-01-29 11:20 - 2013-01-29 11:20 - 00082944 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\cpyamf.util.pyd
2011-07-15 14:37 - 2011-07-15 14:37 - 00981504 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\wx._core_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00746496 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\wx._gdi_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00670720 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\wx._windows_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00966144 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\wx._controls_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00674816 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\wx._misc_.pyd
2012-02-07 11:37 - 2012-02-07 11:37 - 00167424 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\win32gui.pyd
2012-02-07 11:36 - 2012-02-07 11:36 - 00035840 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\win32process.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00688128 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\unicodedata.pyd
2015-04-16 07:29 - 2015-04-16 07:29 - 00061952 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\miniupnpc.pyd
2013-01-29 11:20 - 2013-01-29 11:20 - 00066048 _____ () C:\Users\richard\AppData\Roaming\ACEStream\engine\lib\cpyamf.amf0.pyd
2013-03-04 06:43 - 2011-05-04 22:53 - 01058664 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
2014-12-11 17:40 - 2014-12-11 17:40 - 40622592 ____R () C:\Program Files (x86)\Fitbit Connect\libcef.dll
2011-06-12 08:09 - 2011-06-12 08:09 - 00038400 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\_socket.pyd
2011-06-12 08:09 - 2011-06-12 08:09 - 00720896 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\_ssl.pyd
2011-07-15 14:37 - 2011-07-15 14:37 - 00981504 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\wx._core_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00746496 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\wx._gdi_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00670720 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\wx._windows_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00966144 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\wx._controls_.pyd
2011-07-15 14:38 - 2011-07-15 14:38 - 00674816 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\wx._misc_.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00287232 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\_hashlib.pyd
2011-01-18 16:56 - 2011-01-18 16:56 - 00334336 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\M2Crypto.__m2crypto.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00011776 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\select.pyd
2011-06-12 08:06 - 2011-06-12 08:06 - 00152576 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\pyexpat.pyd
2012-02-07 11:37 - 2012-02-07 11:37 - 00098816 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\win32api.pyd
2012-02-07 11:35 - 2012-02-07 11:35 - 00110080 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\pywintypes27.dll
2012-02-07 11:38 - 2012-02-07 11:38 - 00358912 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\pythoncom27.dll
2012-02-07 11:36 - 2012-02-07 11:36 - 00111616 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\win32file.pyd
2012-02-07 11:36 - 2012-02-07 11:36 - 00024064 _____ () C:\Users\richard\AppData\Roaming\ACEStream\updater\lib\win32pdh.pyd
2016-05-12 02:01 - 2016-05-12 02:01 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9494e643d25019b25b5cf70f2ffc0778\IsdiInterop.ni.dll
2013-03-04 06:37 - 2012-02-01 19:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-03-04 06:32 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2016-08-08 21:17 - 2016-08-02 19:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-08 21:17 - 2016-08-02 19:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2016-08-18 17:08 - 00000859 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-441904776-594677368-125994074-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\richard\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Axis & Allies Registration.lnk => C:\Windows\pss\Axis & Allies Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Launch Utility Application.lnk => C:\Windows\pss\Launch Utility Application.lnk.Startup
MSCONFIG\startupreg: AceStream => C:\Users\richard\AppData\Roaming\ACEStream\engine\ace_engine.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: FAHConsole => C:\Program Files\File Association Helper\FAHConsole.exe
MSCONFIG\startupreg: Fitbit Connect => "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: MouseDriver => TiltWheelMouse.exe
MSCONFIG\startupreg: Open Download Manager => C:\Program Files (x86)\OpenDownloaderManager\odm.exe -autorun
MSCONFIG\startupreg: RtHDVBg_DTS => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /DTSU2P 
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
MSCONFIG\startupreg: WRSVC => "C:\Program Files\Webroot\WRSA.exe" -ul
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C94B7BBA-7528-4065-A327-32837718CFBA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{FEBDE4F8-1509-448A-AD50-B7E09C433AF3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{D780D2D3-2C6E-4A4B-808C-291839ED713A}] => (Allow) svchost.exe
FirewallRules: [{C35302F7-0F1C-4ED8-AB13-F999E2E89E74}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{17D78CF6-8C13-4199-B417-A22E79D2E706}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{59A21C6F-8BA5-40FF-8610-F36A1BD2C743}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E0D16B7F-53C4-40B2-A4F0-90293F41F232}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D05485F0-F03D-4FBB-AA6B-5895DC166E4B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{34F0F95D-C5AB-4BBD-B62B-2E69D7B3DFB0}C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe
FirewallRules: [UDP Query User{F1D0F874-E2A7-430C-B20C-CF01517C8719}C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe
FirewallRules: [TCP Query User{9004CFA8-0179-45DF-BE1D-CB9336CAADC2}C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe
FirewallRules: [UDP Query User{C797A3FF-83DF-4BC2-B50B-B1424012C250}C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\richard\appdata\roaming\acestream\engine\ace_engine.exe
FirewallRules: [{92AB3C72-CC77-4D01-8AA0-D24A134DD3A5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
10-08-2016 03:00:16 Windows Update
16-08-2016 02:04:30 Windows Update
17-08-2016 00:51:52 Windows Update
23-08-2016 02:07:17 Windows Update
26-08-2016 08:04:22 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/27/2016 11:03:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/23/2016 08:53:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/23/2016 05:19:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/22/2016 01:17:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/21/2016 07:11:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2016 09:42:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2016 06:27:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2016 06:21:09 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/15/2016 07:19:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/15/2016 06:24:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (08/27/2016 11:03:11 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel(R) Biometric and Context Agent Service service hung on starting.
 
Error: (08/27/2016 11:01:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error: 
%%2 = The system cannot find the file specified.
 
Error: (08/26/2016 06:07:49 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (08/26/2016 01:00:29 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
 
Error: (08/23/2016 08:53:29 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel(R) Biometric and Context Agent Service service hung on starting.
 
Error: (08/23/2016 08:52:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error: 
%%2 = The system cannot find the file specified.
 
Error: (08/23/2016 05:20:01 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel(R) Biometric and Context Agent Service service hung on starting.
 
Error: (08/23/2016 05:18:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error: 
%%2 = The system cannot find the file specified.
 
Error: (08/23/2016 12:29:20 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR2.
 
Error: (08/22/2016 06:25:04 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR2.
 
 
CodeIntegrity:
===================================
  Date: 2016-08-27 12:26:09.949
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-27 12:16:37.222
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-27 11:54:15.485
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-27 11:35:15.133
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-27 11:14:15.913
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-27 11:02:14.182
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-26 19:39:51.954
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-26 19:06:09.997
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-26 18:46:46.434
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-26 18:26:41.503
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 29%
Total physical RAM: 8132.69 MB
Available physical RAM: 5701.53 MB
Total Virtual: 16263.56 MB
Available Virtual: 13496.5 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:844.5 GB) NTFS
Drive d: (Madame Fate EN) (CDROM) (Total:0.22 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E4B0DEA2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 

These items need to be uninstalled/delete.
OpenDownloadManager
http://www.bleepingcomputer.com/startups/odm.exe-27679.html
free download manager that is known to offer intrusive adware during its installation

Ace Stream Media 3.1.2 (HKU\S-1-5-21-441904776-594677368-125994074-1001\…\AceStream) (Version: 3.1.2 - Ace Stream Media) <==== ATTENTION

If you need help

Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on The Program to remove
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
~~~~~
Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL =
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
U0 SR; no ImagePath
U2 srservice; no ImagePath
U3 aswMBR; \??\C:\Users\richard\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\richard\AppData\Local\Temp\aswVmm.sys [X]
C:\Users\richard\Downloads\firefox-patch.js
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {3690DB9B-BF80-4122-B7A6-6DA6CF55B50B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
Hosts:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~``

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Please download Junkware Removal Tool
    or from here http://downloads.malwarebytes.org/file/jrt
    to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    ~~~
    please post
    Fixlog.txt
    AdwCleaner[C1].txt
    JRT.txt

ok  got all done.  the adwcleaner log says 2 because i accidentally closed it out and made a second one.   thanks

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-08-2016
Ran by [removed] (28-08-2016 12:32:02) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-441904776-594677368-125994074-1001 -> DefaultScope {21A51130-7285-49FE-B3F6-2385CC71CDEA} URL =
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
U0 SR; no ImagePath
U2 srservice; no ImagePath
U3 aswMBR; \??\C:\Users\richard\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\richard\AppData\Local\Temp\aswVmm.sys [X]
C:\Users\richard\Downloads\firefox-patch.js
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {3690DB9B-BF80-4122-B7A6-6DA6CF55B50B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-441904776-594677368-125994074-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
Hosts:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
End
 
Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{21A51130-7285-49FE-B3F6-2385CC71CDEA}" => key removed successfully
HKCR\CLSID\{21A51130-7285-49FE-B3F6-2385CC71CDEA} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{21A51130-7285-49FE-B3F6-2385CC71CDEA}" => key removed successfully
HKCR\Wow6432Node\CLSID\{21A51130-7285-49FE-B3F6-2385CC71CDEA} => key not found. 
HKU\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}" => key removed successfully
HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => key not found. 
SR => service removed successfully
srservice => service removed successfully
aswMBR => service not found.
aswVmm => service not found.
"C:\Users\richard\Downloads\firefox-patch.js" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3690DB9B-BF80-4122-B7A6-6DA6CF55B50B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3690DB9B-BF80-4122-B7A6-6DA6CF55B50B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => key removed successfully
"HKU\.DEFAULT\Software\Classes\exefile" => key removed successfully
"HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully
"HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Classes\.exe" => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktop => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-21-441904776-594677368-125994074-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
========= netsh winsock reset all =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
========= netsh int ipv4 reset =========
 
Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
========= netsh int ipv6 reset =========
 
Reseting Interface, OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
Open FRST/FRST64 and press the > Fix < button just once and wait. => Error: No automatic fix found for this entry.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. => Error: No automatic fix found for this entry.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply. => Error: No automatic fix found for this entry.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9415249 B
Java, Flash, Steam htmlcache => 523 B
Windows/system/drivers => 238100 B
Edge => 0 B
Chrome => 91629641 B
Firefox => 37040251 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 42343782 B
systemprofile32 => 122065 B
LocalService => 0 B
NetworkService => 1742 B
richard => 336200575 B
 
RecycleBin => 114725223 B
EmptyTemp: => 614.5 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
 
# AdwCleaner v6.010 - Logfile created 28/08/2016 at 13:04:34
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-28.2 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : richard - RICHARD-PC
# Running from : C:\Users\richard\Desktop\whatthetechstuff\AdwCleaner.exe
# Mode: Scan
 
 
 
***** [ Services ] *****
 
No malicious services found.
 
 
***** [ Folders ] *****
 
No malicious folders found.
 
 
***** [ Files ] *****
 
No malicious files found.
 
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
 
***** [ WMI ] *****
 
No malicious keys found.
 
 
***** [ Shortcuts ] *****
 
No infected shortcut found.
 
 
***** [ Scheduled Tasks ] *****
 
No malicious task found.
 
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
 
***** [ Web browsers ] *****
 
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [3498 Bytes] - [28/08/2016 12:49:26]
C:\AdwCleaner\AdwCleaner[S0].txt - [3290 Bytes] - [28/08/2016 12:43:21]
C:\AdwCleaner\AdwCleaner[S1].txt - [3361 Bytes] - [28/08/2016 12:45:00]
C:\AdwCleaner\AdwCleaner[S2].txt - [1233 Bytes] - [28/08/2016 13:04:34]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1306 Bytes] ##########
 
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Sun 08/28/2016 at 13:33:46.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 10 
 
Successfully deleted: C:\Users\richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm (Folder) 
Successfully deleted: C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\extensions\[removed] (Folder) 
Successfully deleted: C:\Users\richard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3SYXJSRS (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\richard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7G7A642X (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\richard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B5VY49IL (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\richard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I5BS17B7 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3SYXJSRS (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7G7A642X (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B5VY49IL (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I5BS17B7 (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 08/28/2016 at 13:35:13.64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
Let's update and run a fresh scan with Malwarebytes Anti-Malware
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.

~~~~~~~~
Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop.
Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.
  • Leave all settings as they are and click the Extract button at the bottom.
  • A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
  • Please click Yes so that it downloads the latest database updates.
  • When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
  • Click on Scan to be taken to the scan options.
  • If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
  • Click on the Malware Scan button to start the scan.
  • When the scan is completed click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop, and copy it to your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.
Are you seeing any improvements?
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 8/28/2016
Scan Time: 7:20 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.08.28.08
Rootkit Database: v2016.08.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: richard
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 306343
Time Elapsed: 6 min, 29 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 24
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);), Replaced,[007874dca8f20c2abd1c6d6c749012ee]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (e application is running,
 * the changes will be overwrittennces, you c), Replaced,[07719eb23f5b5cda2bae7564fe06936d]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: ( application is running,
 * the changes will be overwrittennces, you can visit th), Replaced,[e59357f9c5d5b2847267e3f65ba99a66]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (on is running,
 * the changes will be overwrittennces, you can visit the URL about:config
 ), Replaced,[cdab6be5cfcbad89ae2b0bcef410fc04]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (ng,
 * the changes will be overwrittennces, you can visit the URL about:config
 */
 
user_pref(), Replaced,[4137e36d1b7fa591d8016a6ffe06817f]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: ( * the changes will be overwrittennces, you can visit the URL about:config
 */
 
user_pref("app.update.lastU), Replaced,[0e6a2b256832f2443e9b19c0c2425aa6]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (es will be overwrittennces, you can visit the URL about:config
 */
 
user_pref(), Replaced,[d5a3e16f6436b97d12c7617812f2619f]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (ion is running,
 * the changes will be overwrittennces, you can visit the URL about:config
 */
 
user_pref("app.up), Replaced,[d1a796ba1c7e1e1802d7a33633d18878]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: ( be overwrittennces, you can visit the URL about:config
 */
 
user_pref("app.update.), Replaced,[1563b69a83177fb75188ddfc8183649c]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (s running,
 * the changes will be overwrittennces, you can visit the URL about:co), Replaced,[ff7965ebd7c32f07e3f6d00937cdc838]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (on is running,
 * the changes will be overwrittennces, you can visit the URL about:), Replaced,[e692163aefabaa8cebeee5f4ac5844bc]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: ( is running,
 * the changes will be overwrittennces, you can visit the URL about:c), Replaced,[c8b04c043367b08608d15089d133a759]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (n is running,
 * the changes will be overwrittennces, you can visit the URL ab), Replaced,[96e249072d6dc86e34a5598027ddde22]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (ation is running,
 * the changes will be overwrittennces, you can visit the URL), Replaced,[4335ca86b8e2f541c9104e8b1aea44bc]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (tion is running,
 * the changes will be overwrittennces, you can visit the URL about:config
 */
 
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1439518524);
user_pref("app.updat), Replaced,[aacedb75cad06dc96079776223e160a0]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (astUpdateTime.addon-background-update-timer", 1439518524);
user_pref("a), Replaced,[f1873818cfcb1b1b83567c5d54b06f91]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (s running,
 * the changes will be overwrittennces, you can visit the URL about:con), Replaced,[aecaee628416a1951cbd2bae6e96847c]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (n is running,
 * the changes will be overwrittennces, you can visit the URL about:co), Replaced,[4a2e70e073274beb29b01fba19eba858]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (is running,
 * the changes will be overwrittennces, you can visit the URL about:con), Replaced,[9cdc2a26554548eefcddebeedd277987]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: ( is running,
 * the changes will be overwrittennces, you can visit the URL abou), Replaced,[ec8c51ffa7f373c3ad2c63764db756aa]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (tion is running,
 * the changes will be overwrittennces, you can visit the URL ), Replaced,[2f4964ec62383bfb80597861f311a759]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (tion is running,
 * the changes will be overwrittennces, yo), Replaced,[20588ac64951f44229b0ab2e9f65768a]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (nces
 
/* e application is running,
 * the changes will be o), Replaced,[195ff65af9a1979ff6e38e4b7d870bf5]
PUP.Optional.MindSpark.Generic, C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\rhtphmuc.default\prefs.js, Good: (), Bad: (es
 
/* e application is running,
 * the changes will be overwrittennces, you can vis), Replaced,[f28662eeb5e5ae88885192475ca8a35d]
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
 
Emsisoft Emergency Kit - Version 11.9
Last update: 8/28/2016 7:42:14 PM
User account: richard-PC\richard
Computer name: RICHARD-PC
OS version: Windows 7x64 Service Pack 1
 
Scan settings:
 
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
 
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
 
Scan start: 8/28/2016 7:43:08 PM
C:\Program Files (x86)\GameSpy Arcade\ detected: Adware.Win32.Gaspacade (A)
C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade\ detected: Adware.Win32.Gaspacade (A)
C:\Users\richard\Desktop\GameSpy Arcade.lnk detected: Adware.Win32.Gaspacade (A)
Key: HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\GAMESPY\GAMESPY ARCADE detected: Adware.Win32.Gaspacade (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GAMESPY ARCADE detected: Adware.Win32.Gaspacade (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLECMD detected: Setting.DisableCMD (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLECMD detected: Setting.DisableCMD (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLECMD detected: Setting.DisableCMD (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLECMD detected: Setting.DisableCMD (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NORUN detected: Setting.NoRun (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_USERS\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_USERS\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_USERS\S-1-5-21-441904776-594677368-125994074-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER -> NOFOLDEROPTIONS detected: Setting.NoFolderOptions (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{34AD1EA7-8B9E-4D8B-B3ED-365D12C8EE73} detected: Application.AdTool (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{47700C35-9E3E-4DAD-934C-0CE28A87237C} detected: Application.AdTool (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4} detected: Application.AdTool (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{7FCD22A8-B70A-4AC7-AAF1-EBCCD2F6612D} detected: Application.AdTool (A)
 
Scanned 74361
Found 41
 
Scan end: 8/28/2016 7:45:38 PM
Scan time: 0:02:30
 
Your good to go

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
************************************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • [external image: JEP5iWI.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Need a second opinion on a file or website? Scan the file/URL before clicking by using one of the following free online scanner services.
  • [external image: nWhGEI3.png]VirusTotal (File & URL)
  • [external image: MJUfyKX.png]Jotti's Malware Scan (File)
  • [external image: XeTvs74.png]Dr.Web Online Check (URL)
  • [external image: 5v676cC.png]Trend Micro Site Safety Center (URL)
  • [external image: 2tXp7dz.png] Norton Safe Web (URL)
Want to help others? Join the ClassRoom and learn how.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI